Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2021-28692
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such…
Xen
Mitigation only
HIGH 7.8
CVE-2021-35523
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYST…
Openvpn Client
2.0.32+
HIGH 8.8
CVE-2021-33538
In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settin…
Ie Wl Bl Ap Cl Eu Firmware
after 1.16.18
HIGH 7.8
CVE-2021-35448
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder fe…
Emote Interactive Studio
No fix yet
HIGH 8.8
CVE-2021-23999
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges t…
Firefox
78.10 / 88.0+
MEDIUM 6.5
CVE-2021-29951
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start …
Firefox
78.10.1 / 87.0+
HIGH 8.8
CVE-2021-25650
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially craft…
Aura Utility Services
after 7.1.3
HIGH 7.8
CVE-2021-25651
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Af…
Aura Utility Services
after 7.1.3
HIGH 8.8
CVE-2021-34810
Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to exe…
Download Station
3.8.16-3566+
HIGH 7.8
CVE-2021-27483
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to…
Defibrillator Dashboard
2.2+
HIGH 7.8
CVE-2021-25418
Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activit…
Internet
14.0.1.62+
HIGH 8.8
CVE-2021-28814
An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise…
Helpdesk
3.0.4+
HIGH 7.8
CVE-2021-0052
Incorrect default privileges in the Intel(R) Computing Improvement Program before version 2.4.6522 may allow an authenticated user to potentially ena…
Computing Improvement Program
2.4.6522+
HIGH 8.8
CVE-2021-33356EPSS 5%
Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /in…
Raspap
after 2.6.5
HIGH 7.8
CVE-2021-31969
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows 10
Patch available
HIGH 7.8
CVE-2021-31954
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows 10
Patch available
HIGH 8.8
CVE-2021-27657
Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allow…
Metasys
after 11.0
HIGH 7.8
CVE-2013-4536
An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on…
Qemu
1.5.3+
HIGH 7.8
CVE-2021-22118
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation:…
Spring Framework
5.2.15 / 5.3.7+
HIGH 7.8
CVE-2021-22732
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue…
Spacelynk Firmware
after 2.6.0
HIGH 7.8
CVE-2021-22733
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unau…
Spacelynk Firmware
after 2.6.0
HIGH 7.8
CVE-2018-16497
In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as…
Versa Analytics
Mitigation only
CRITICAL 9.8
CVE-2020-28904
Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious co…
Fusion
after 4.1.8
HIGH 7.8
CVE-2021-20713
Privilege escalation vulnerability in QND Advance/Premium/Standard Ver.11.0.4i and earlier allows an attacker who can log in to the PC where the prod…
Qnd
after 11.0.4i
HIGH 8.8
CVE-2021-24289
There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their us…
Store Locator Plus
after 5.5.14
HIGH 7.8
CVE-2021-23891
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating…
Total Protection
16.0.32+
HIGH 7.8
CVE-2021-31168
Windows Container Manager Service Elevation of Privilege Vulnerability
Windows 10
Patch available
HIGH 7.8
CVE-2021-31169
Windows Container Manager Service Elevation of Privilege Vulnerability
Windows 10
Patch available
MEDIUM 5.5
CVE-2021-21430
OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an Op…
Openapi Generator
5.1.1+
HIGH 7.0
CVE-2021-21428
Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documentation and configuration auto…
Openapi Generator
5.1.0+